diff --git a/roles/unbound/files/unbound.conf b/roles/unbound/files/unbound.conf new file mode 100644 index 0000000..a3c7152 --- /dev/null +++ b/roles/unbound/files/unbound.conf @@ -0,0 +1,58 @@ +server: + verbosity: 3 + port: 5353 + interface: 127.0.0.1 + #interface: 10.1.0.1 + do-ip4: yes + do-ip6: no + do-udp: yes + do-tcp: yes + num-threads: 4 + msg-cache-slabs: 4 + rrset-cache-slabs: 4 + infra-cache-slabs: 4 + key-cache-slabs: 4 + msg-cache-size: 64m + rrset-cache-size: 128m + key-cache-size: 32m + neg-cache-size: 4m + cache-min-ttl: 300 + cache-max-ttl: 86400 + prefetch: yes + prefetch-key: yes + serve-expired: yes + edns-buffer-size: 1232 + so-reuseport: yes + auto-trust-anchor-file: "/var/lib/unbound/root.key" + harden-glue: yes + harden-dnssec-stripped: yes + qname-minimisation: yes + hide-identity: yes + hide-version: yes + tls-system-cert: yes + pad-queries: yes + pad-queries-block-size: 128 + access-control: 127.0.0.0/8 allow + access-control: 10.0.0.0/8 allow + local-zone: "10.0.in-addr.arpa." nodefault + local-zone: "lan." static + insecure-lan-zones: yes + ip-ratelimit: 200 + ip-ratelimit-slabs: 4 + tcp-connection-limit: 10.0.0.0/8 64 + +forward-zone: + name: "brawlstarsgame.com" + forward-tls-upstream: yes + forward-addr: 45.139.239.56@853#dns.nullsproxy.com + forward-addr: 141.95.97.120@853#dns.nullsproxy.com + forward-addr: 179.43.147.42@853#dns.nullsproxy.com + forward-addr: 185.211.245.131@853#dns.nullsproxy.com + forward-addr: 82.27.0.149@853#dns.nullsproxy.com + forward-addr: 81.17.20.83@853#dns.nullsproxy.com + +forward-zone: + name: "." + forward-tls-upstream: yes + forward-addr: 1.1.1.1@853#cloudflare-dns.com + forward-addr: 1.0.0.1@853#cloudflare-dns.com diff --git a/roles/unbound/handlers/main.yml b/roles/unbound/handlers/main.yml new file mode 100644 index 0000000..714e530 --- /dev/null +++ b/roles/unbound/handlers/main.yml @@ -0,0 +1,6 @@ +--- +- name: restart unbound + ansible.builtin.service: + name: unbound + state: restarted + listen: restart unbound diff --git a/roles/unbound/tasks/configure.yml b/roles/unbound/tasks/configure.yml new file mode 100644 index 0000000..d4464be --- /dev/null +++ b/roles/unbound/tasks/configure.yml @@ -0,0 +1,15 @@ +--- +- name: ensure /etc/unbound exists + ansible.builtin.file: + path: /etc/unbound + state: directory + mode: "0755" + +- name: deploy unbound config + ansible.builtin.copy: + src: "{{ item }}" + dest: "/etc/unbound/{{ item }}" + mode: "0744" + loop: + - unbound.conf + notify: restart unbound diff --git a/roles/unbound/tasks/install.yml b/roles/unbound/tasks/install.yml new file mode 100644 index 0000000..bf9843b --- /dev/null +++ b/roles/unbound/tasks/install.yml @@ -0,0 +1,5 @@ +--- +- name: install unbound + ansible.builtin.package: + name: unbound + state: present diff --git a/roles/unbound/tasks/main.yml b/roles/unbound/tasks/main.yml new file mode 100644 index 0000000..c011b41 --- /dev/null +++ b/roles/unbound/tasks/main.yml @@ -0,0 +1,6 @@ +--- +- name: include unbound install + ansible.builtin.include_tasks: install.yml + +- name: include unbound configurure + ansible.builtin.include_tasks: configure.yml